home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Collection of Tools & Utilities
/
Collection of Tools and Utilities.iso
/
dskut
/
tbfence1.zip
/
TBFENCE.DOC
< prev
next >
Wrap
Text File
|
1993-08-25
|
28KB
|
716 lines
TbFence user manual (C) Copyright 1993 Thunderbyte B.V.
INTRODUCTION . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
How does it work? . . . . . . . . . . . . . . . . . . . . . . 1
Some questions . . . . . . . . . . . . . . . . . . . . . . . . 2
Quick initial installation . . . . . . . . . . . . . . . . . . 3
TbFence demonstration . . . . . . . . . . . . . . . . . . . . 3
USAGE OF TBFENCE . . . . . . . . . . . . . . . . . . . . . . . . . 5
System requirements . . . . . . . . . . . . . . . . . . . . . 5
Predefined configurations . . . . . . . . . . . . . . . . . . 5
Program invocation . . . . . . . . . . . . . . . . . . . . . . 6
Installation . . . . . . . . . . . . . . . . . . . . . . . . . 6
De-installation . . . . . . . . . . . . . . . . . . . . . . . 7
Status of diskette . . . . . . . . . . . . . . . . . . . . . . 7
Encrypt a diskette . . . . . . . . . . . . . . . . . . . . . . 7
Decrypt a diskette . . . . . . . . . . . . . . . . . . . . . . 8
Options menu . . . . . . . . . . . . . . . . . . . . . . . . . 8
Format to normal . . . . . . . . . . . . . . . . . . . . . . . 8
Setup temporary gateway . . . . . . . . . . . . . . . . . . . 8
ADDITIONAL INFORMATION . . . . . . . . . . . . . . . . . . . . . . 9
Formatting diskettes . . . . . . . . . . . . . . . . . . . . . 9
Bootable diskettes . . . . . . . . . . . . . . . . . . . . . . 9
The TbFence.Sys device driver . . . . . . . . . . . . . . . . 9
Viruses and Anti-Virus products . . . . . . . . . . . . . . . 9
The encryption scheme . . . . . . . . . . . . . . . . . . . . 10
Exit codes . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Error messages . . . . . . . . . . . . . . . . . . . . . . . . 11
TbFence user manual (C) Copyright 1993 Thunderbyte B.V.
INTRODUCTION
Nearly every PC is equipped with one or more diskette drives. While a
diskette drive is necessary for maintenance and upgrading, it may also
be used to introduce malicious software into the system, copy software
owned by the company, or even to export confidential information.
Many companies have had unfortunate experiences with computer viruses,
leaked information, or pilferage of software. For this reason many
companies fiddle with diskless workstations, mechanical locks on the
diskette drives, etc. While these measures prevent the introduction of
malicious software or export of company properties, it is now also hard
to transfer data from one desk to another, and to perform maintenance
like upgrading software.
TbFence was developed to solve these problems neatly. With TbFence you
build a fence around your company or departments. Between the borders of
this fence the data flow is not affected, but data can not cross the
fence. A fence has a gate, and of course TbFence also offers you one.
You may setup one workstation as a 'gateway' station. This gateway
station can be used to import or export diskettes, of course under your
control and after examination of the contents of the diskette!
How does it work?
TbFence is actually a transparent data encryption/decryption mechanism.
Once you have installed TbFence, all data going to the diskette drive
will be encrypted automatically, and all data read from the diskette
drive will be decrypted as well. This background encryption and/or
decryption is completely transparent to the user. If you don't tell the
user, he will not even notice that something has been changed, until he
tries to insert his unauthorized game diskette. TbFence will simply
refuse to read from or write to this diskette. If the user copies
information to a diskette, this diskette can be read on other machines
equipped with TbFence, but when he tries to read the diskette at home,
he will find out that it is impossible to read it. He is however still
able to share the TbFenced diskettes with other employees of the compa-
ny.
+-----------------------------+
| # | #
| # TbFenced machines # | # The 'outside' world
| |
| #
| # # |\gateway station
| # |
| # # | #
| |
+-----------------------------+
1
TbFence user manual (C) Copyright 1993 Thunderbyte B.V.
All machines between the TbFence borders can share diskettes, but to
export diskettes to the 'outside' world, the diskettes have to pass
through the 'gateway' station where they can be examined before allowing
the conversion. The same applies to the import of diskettes. No diskette
can enter the area within the 'fence' without autohorization by the
gateway.
Some questions
By now some questions have probably entered your mind. Hopefully they
will be answered by the sample questions listed below.
Q: How can I import or export diskettes?
A: The supervisor can temporarily override the settings of TbFence and
allow it to use normal disks. You can also setup a permanent
gateway station which can be used to convert diskettes, of course
under control of the supervisor!
Q: Are my employees able to remove TbFence?
A: TbFence is installed on the master boot record of your hard disk.
When you install TbFence you have to enter a password. You need to
know this password when you want to remove TbFence. Low level disk
utilities can not be used to remove TbFence.
Q: What if the user boots from a non-authorized diskette?
A: TbFence hides the partition information of your hard disk. If you
boot from an unauthorized diskette the partition information is not
available and the user is not able to access the hard disk.
Q: What if I need to reboot from a diskette?
A: You can reboot from a diskette if this diskette has been converted
by TbFence, or when this diskette has been created on a TbFence
machine. When you boot from such a diskette, the hard disk will be
available, and the installed configuration of TbFence will still be
applied, as if the user booted from the hard disk. So, if the user
is normally not allowed to read normal diskettes, he is still not
able to do so after a diskette boot. Remember, TbFence is complete-
ly transparent to the user!
Q: What if my employees install TbFence at their machines at home?
A: The password you need to enter when you install TbFence is also
used as an encryption key. This means that if the employees do not
install TbFence with the same password as the TbFence on the compa-
ny's PC, they still can't use the diskettes.
Q: Once installed, can I remove TbFence from my system after the
evaluation?
A: Sure. You can remove TbFence from your system, leaving no trace, if
you enter the correct password.
2
TbFence user manual (C) Copyright 1993 Thunderbyte B.V.
Q: What problems can I expect when using TbFence?
A: Unlike some other 'Fence' products, TbFence has been implemented as
very low level system software and works independent of the opera-
ting system. Therefore TbFence is not affected at all by software
like Windows, disk doublers, etc. It is very